swagger: '2.0' info: title: Applications.Core Management APIs ApiVersions SecretStores API version: 2023-10-01-preview description: REST APIs for Applications.Core x-typespec-generated: - emitter: '@azure-tools/typespec-autorest' host: management.azure.com schemes: - https consumes: - application/json produces: - application/json security: - azure_auth: - user_impersonation tags: - name: SecretStores paths: /{rootScope}/providers/Applications.Core/secretStores: get: operationId: SecretStores_ListByScope tags: - SecretStores description: List SecretStoreResource resources by Scope parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/SecretStoreResourceListResult' default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: List secret stores: $ref: ./examples/SecretStores_List.json x-ms-pageable: nextLinkName: nextLink /{rootScope}/providers/Applications.Core/secretStores/{secretStoreName}: get: operationId: SecretStores_Get tags: - SecretStores description: Get a SecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/SecretStoreResource' default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Get a secret store: $ref: ./examples/SecretStores_Get.json Get a secret store for Azure Keyvault: $ref: ./examples/SecretStores_Get_AzureKeyVault.json put: operationId: SecretStores_CreateOrUpdate tags: - SecretStores description: Create a SecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ - name: resource in: body description: Resource create parameters. required: true schema: $ref: '#/definitions/SecretStoreResource' responses: '200': description: Resource 'SecretStoreResource' update operation succeeded schema: $ref: '#/definitions/SecretStoreResource' '201': description: Resource 'SecretStoreResource' create operation succeeded schema: $ref: '#/definitions/SecretStoreResource' headers: Azure-AsyncOperation: type: string description: A link to the status monitor Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Create or Update a secret store resource with azure keyvault: $ref: ./examples/SecretStores_CreateOrUpdate.json Create or Update a secret store resource with global scope: $ref: ./examples/SecretStores_CreateOrUpdate_GlobalScope.json Create or Update a secret store resource with valueFrom: $ref: ./examples/SecretStores_CreateOrUpdateValueFrom.json x-ms-long-running-operation-options: final-state-via: azure-async-operation x-ms-long-running-operation: true patch: operationId: SecretStores_Update tags: - SecretStores description: Update a SecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ - name: properties in: body description: The resource properties to be updated. required: true schema: $ref: '#/definitions/SecretStoreResourceUpdate' responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/SecretStoreResource' '202': description: Resource update request accepted. headers: Location: type: string description: The Location header contains the URL where the status of the long running operation can be checked. Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Update a secret store: $ref: ./examples/SecretStores_Update.json Update a secret store resource: $ref: ./examples/SecretStores_Delete.json x-ms-long-running-operation-options: final-state-via: location x-ms-long-running-operation: true delete: operationId: SecretStores_Delete tags: - SecretStores description: Delete a SecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ responses: '202': description: Resource deletion accepted. headers: Location: type: string description: The Location header contains the URL where the status of the long running operation can be checked. Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. '204': description: Resource does not exist. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-long-running-operation-options: final-state-via: location x-ms-long-running-operation: true /{rootScope}/providers/Applications.Core/secretStores/{secretStoreName}/listSecrets: post: operationId: SecretStores_ListSecrets tags: - SecretStores description: List the secrets of a secret stores. parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ - name: body in: body description: The content of the action request required: true schema: type: object responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/SecretStoreListSecretsResult' default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: List secret stores: $ref: ./examples/SecretStores_ListSecrets.json /{rootScope}/providers/Applications.Dapr/secretStores: get: operationId: SecretStores_ListByScope tags: - SecretStores description: List DaprSecretStoreResource resources by Scope parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/DaprSecretStoreResourceListResult' default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: List SecretStore resources by resource group: $ref: ./examples/SecretStores_List.json List SecretStore resources by rootScope: $ref: ./examples/SecretStores_ListByRootScope.json x-ms-pageable: nextLinkName: nextLink /{rootScope}/providers/Applications.Dapr/secretStores/{secretStoreName}: get: operationId: SecretStores_Get tags: - SecretStores description: Get a DaprSecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/DaprSecretStoreResource' default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Get a SecretStore resource: $ref: ./examples/SecretStores_Get.json put: operationId: SecretStores_CreateOrUpdate tags: - SecretStores description: Create a DaprSecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ - name: resource in: body description: Resource create parameters. required: true schema: $ref: '#/definitions/DaprSecretStoreResource' responses: '200': description: Resource 'DaprSecretStoreResource' update operation succeeded schema: $ref: '#/definitions/DaprSecretStoreResource' '201': description: Resource 'DaprSecretStoreResource' create operation succeeded schema: $ref: '#/definitions/DaprSecretStoreResource' headers: Azure-AsyncOperation: type: string description: A link to the status monitor Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Create or update an SecretStore resource: $ref: ./examples/SecretStores_CreateOrUpdate.json x-ms-long-running-operation-options: final-state-via: azure-async-operation x-ms-long-running-operation: true patch: operationId: SecretStores_Update tags: - SecretStores description: Update a DaprSecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ - name: properties in: body description: The resource properties to be updated. required: true schema: $ref: '#/definitions/DaprSecretStoreResourceUpdate' responses: '200': description: Azure operation completed successfully. schema: $ref: '#/definitions/DaprSecretStoreResource' '202': description: Resource update request accepted. headers: Location: type: string description: The Location header contains the URL where the status of the long running operation can be checked. Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Update an SecretStore resource: $ref: ./examples/SecretStores_Update.json x-ms-long-running-operation-options: final-state-via: location x-ms-long-running-operation: true delete: operationId: SecretStores_Delete tags: - SecretStores description: Delete a DaprSecretStoreResource parameters: - $ref: ../../../../../common-types/resource-management/v3/types.json#/parameters/ApiVersionParameter - $ref: '#/parameters/RootScopeParameter' - name: secretStoreName in: path description: SecretStore name required: true type: string maxLength: 63 pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ responses: '202': description: Resource deletion accepted. headers: Location: type: string description: The Location header contains the URL where the status of the long running operation can be checked. Retry-After: type: integer format: int32 description: The Retry-After header can indicate how long the client should wait before polling the operation status. '204': description: Resource does not exist. default: description: An unexpected error response. schema: $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/ErrorResponse x-ms-examples: Delete a SecretStore resource: $ref: ./examples/SecretStores_Delete.json x-ms-long-running-operation-options: final-state-via: location x-ms-long-running-operation: true definitions: SecretStoreResourceListResult: type: object description: The response of a SecretStoreResource list operation. properties: value: type: array description: The SecretStoreResource items on this page items: $ref: '#/definitions/SecretStoreResource' nextLink: type: string format: uri description: The link to the next page of items required: - value DaprSecretStoreResource: type: object description: Dapr SecretStore portable resource properties: properties: $ref: '#/definitions/DaprSecretStoreProperties' description: The resource-specific properties for this resource. x-ms-client-flatten: true x-ms-mutability: - read - create required: - properties allOf: - $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/TrackedResource RecipeStatus: type: object description: Recipe status at deployment time for a resource. properties: templateKind: type: string description: TemplateKind is the kind of the recipe template used by the portable resource upon deployment. templatePath: type: string description: TemplatePath is the path of the recipe consumed by the portable resource upon deployment. templateVersion: type: string description: TemplateVersion is the version number of the template. required: - templateKind - templatePath OutputResource: type: object description: Properties of an output resource. properties: localId: type: string description: The logical identifier scoped to the owning Radius resource. This is only needed or used when a resource has a dependency relationship. LocalIDs do not have any particular format or meaning beyond being compared to determine dependency relationships. id: type: string description: The UCP resource ID of the underlying resource. radiusManaged: type: boolean description: Determines whether Radius manages the lifecycle of the underlying resource. EnvironmentCompute: type: object description: Represents backing compute resource properties: kind: type: string description: Discriminator property for EnvironmentCompute. resourceId: type: string description: The resource id of the compute resource for application environment. identity: $ref: '#/definitions/IdentitySettings' description: Configuration for supported external identity providers discriminator: kind required: - kind IdentitySettingKind: type: string description: IdentitySettingKind is the kind of supported external identity setting enum: - undefined - azure.com.workload - userAssigned - systemAssigned - systemAssignedUserAssigned x-ms-enum: name: IdentitySettingKind modelAsString: false values: - name: undefined value: undefined description: undefined identity - name: azure.com.workload value: azure.com.workload description: azure ad workload identity - name: userAssigned value: userAssigned description: User assigned managed identity - name: systemAssigned value: systemAssigned description: System assigned managed identity - name: systemAssignedUserAssigned value: systemAssignedUserAssigned description: System assigned and user assigned managed identity DaprSecretStoreResourceUpdate: type: object description: Dapr SecretStore portable resource allOf: - $ref: '#/definitions/Azure.ResourceManager.CommonTypes.TrackedResourceUpdate' SecretStoreResourceUpdate: type: object description: Concrete tracked resource types can be created by aliasing this type using a specific property type. allOf: - $ref: '#/definitions/Azure.ResourceManager.CommonTypes.TrackedResourceUpdate' MetadataValueFromSecret: type: object description: A reference of a value in a secret store component. properties: name: type: string description: Secret name in the secret store component key: type: string description: The field to select in the secret value. If the secret value is a string, it should be equal to the secret name required: - name - key SecretStoreProperties: type: object description: The properties of SecretStore properties: environment: type: string description: Fully qualified resource ID for the environment that the application is linked to application: type: string description: Fully qualified resource ID for the application provisioningState: $ref: '#/definitions/ProvisioningState' description: The status of the asynchronous operation. readOnly: true status: $ref: '#/definitions/ResourceStatus' description: Status of a resource. readOnly: true type: type: string description: The type of secret store data default: generic enum: - generic - certificate - basicAuthentication - azureWorkloadIdentity - awsIRSA x-ms-enum: name: SecretStoreDataType modelAsString: false values: - name: generic value: generic description: Generic secret data type - name: certificate value: certificate description: Certificate secret data type - name: basicAuthentication value: basicAuthentication description: basicAuthentication type is used to represent username and password based authentication and the secretstore resource is expected to have the keys 'username' and 'password'. - name: azureWorkloadIdentity value: azureWorkloadIdentity description: azureWorkloadIdentity type is used to represent authentication using azure federated identity and the secretstore resource is expected to have the keys 'clientId' and 'tenantId'. - name: awsIRSA value: awsIRSA description: awsIRSA type is used to represent authentication using AWS IRSA (IAM Roles for Service accounts) and the secretstore resource is expected to have the key 'roleARN'. data: type: object description: An object to represent key-value type secrets additionalProperties: $ref: '#/definitions/SecretValueProperties' resource: type: string description: The resource id of external secret store. required: - data SecretStoreDataType: type: string description: The type of SecretStore data enum: - generic - certificate - basicAuthentication - azureWorkloadIdentity - awsIRSA x-ms-enum: name: SecretStoreDataType modelAsString: false values: - name: generic value: generic description: Generic secret data type - name: certificate value: certificate description: Certificate secret data type - name: basicAuthentication value: basicAuthentication description: basicAuthentication type is used to represent username and password based authentication and the secretstore resource is expected to have the keys 'username' and 'password'. - name: azureWorkloadIdentity value: azureWorkloadIdentity description: azureWorkloadIdentity type is used to represent authentication using azure federated identity and the secretstore resource is expected to have the keys 'clientId' and 'tenantId'. - name: awsIRSA value: awsIRSA description: awsIRSA type is used to represent authentication using AWS IRSA (IAM Roles for Service accounts) and the secretstore resource is expected to have the key 'roleARN'. DaprSecretStoreResourceListResult: type: object description: The response of a DaprSecretStoreResource list operation. properties: value: type: array description: The DaprSecretStoreResource items on this page items: $ref: '#/definitions/DaprSecretStoreResource' nextLink: type: string format: uri description: The link to the next page of items required: - value ResourceStatus: type: object description: Status of a resource. properties: compute: $ref: '#/definitions/EnvironmentCompute' description: The compute resource associated with the resource. recipe: $ref: '#/definitions/RecipeStatus' description: The recipe data at the time of deployment readOnly: true outputResources: type: array description: Properties of an output resource items: $ref: '#/definitions/OutputResource' x-ms-identifiers: [] ValueFromProperties: type: object description: The Secret value source properties properties: name: type: string description: The name of the referenced secret. version: type: string description: The version of the referenced secret. required: - name ResourceProvisioning: type: string description: Specifies how the underlying service/resource is provisioned and managed. Available values are 'recipe', where Radius manages the lifecycle of the resource through a Recipe, and 'manual', where a user manages the resource and provides the values. enum: - recipe - manual x-ms-enum: name: ResourceProvisioning modelAsString: false values: - name: recipe value: recipe description: The resource lifecycle will be managed by Radius - name: manual value: manual description: The resource lifecycle will be managed by the user Recipe: type: object description: The recipe used to automatically deploy underlying infrastructure for a portable resource properties: name: type: string description: The name of the recipe within the environment to use parameters: type: object description: Key/value parameters to pass into the recipe at deployment required: - name Azure.ResourceManager.CommonTypes.TrackedResourceUpdate: type: object title: Tracked Resource description: The resource model definition for an Azure Resource Manager tracked top level resource which has 'tags' and a 'location' properties: tags: type: object description: Resource tags. additionalProperties: type: string allOf: - $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/Resource SecretStoreListSecretsResult: type: object description: The list of secrets properties: type: $ref: '#/definitions/SecretStoreDataType' description: The type of secret store data data: type: object description: An object to represent key-value type secrets additionalProperties: $ref: '#/definitions/SecretValueProperties' required: - type - data SecretValueProperties: type: object description: The properties of SecretValue properties: encoding: type: string description: The encoding of value default: raw enum: - raw - base64 x-ms-enum: name: SecretValueEncoding modelAsString: false values: - name: raw value: raw description: The raw secret value - name: base64 value: base64 description: The base64-encoded secret value value: type: string format: password description: The value of secret. x-ms-secret: true valueFrom: $ref: '#/definitions/ValueFromProperties' description: The referenced secret in properties.resource SecretStoreResource: type: object description: Concrete tracked resource types can be created by aliasing this type using a specific property type. properties: properties: $ref: '#/definitions/SecretStoreProperties' description: The resource-specific properties for this resource. x-ms-client-flatten: true x-ms-mutability: - read - create required: - properties allOf: - $ref: ../../../../../common-types/resource-management/v3/types.json#/definitions/TrackedResource ProvisioningState: type: string description: Provisioning state of the resource at the time the operation was called enum: - Creating - Updating - Deleting - Accepted - Provisioning - Succeeded - Failed - Canceled x-ms-enum: name: ProvisioningState modelAsString: false values: - name: Creating value: Creating description: The resource is being created - name: Updating value: Updating description: The resource is being updated - name: Deleting value: Deleting description: The resource is being deleted - name: Accepted value: Accepted description: The resource create request has been accepted - name: Provisioning value: Provisioning description: The resource is being provisioned - name: Succeeded value: Succeeded description: The resource has been successfully provisioned - name: Failed value: Failed description: The resource provisioning has failed - name: Canceled value: Canceled description: The resource provisioning has been canceled readOnly: true IdentitySettings: type: object description: IdentitySettings is the external identity setting. properties: kind: $ref: '#/definitions/IdentitySettingKind' description: kind of identity setting oidcIssuer: type: string description: The URI for your compute platform's OIDC issuer resource: type: string description: The resource ID of the provisioned identity managedIdentity: type: array description: The list of user assigned managed identities items: type: string required: - kind DaprSecretStoreProperties: type: object description: Dapr SecretStore portable resource properties properties: environment: type: string description: Fully qualified resource ID for the environment that the portable resource is linked to application: type: string description: Fully qualified resource ID for the application that the portable resource is consumed by (if applicable) provisioningState: $ref: '#/definitions/ProvisioningState' description: The status of the asynchronous operation. readOnly: true status: $ref: '#/definitions/ResourceStatus' description: Status of a resource. readOnly: true componentName: type: string description: The name of the Dapr component object. Use this value in your code when interacting with the Dapr client to use the Dapr component. readOnly: true metadata: type: object description: The metadata for Dapr resource which must match the values specified in Dapr component spec additionalProperties: $ref: '#/definitions/MetadataValue' type: type: string description: Dapr component type which must matches the format used by Dapr Kubernetes configuration format version: type: string description: Dapr component version recipe: $ref: '#/definitions/Recipe' description: The recipe used to automatically deploy underlying infrastructure for the resource resourceProvisioning: $ref: '#/definitions/ResourceProvisioning' description: Specifies how the underlying service/resource is provisioned and managed. required: - environment MetadataValue: type: object description: A single metadata for a Dapr component object properties: value: type: string description: The plain text value of the metadata secretKeyRef: $ref: '#/definitions/MetadataValueFromSecret' description: A reference of a value in a secret store component parameters: RootScopeParameter: name: rootScope in: path description: The scope in which the resource is present. UCP Scope is /planes/{planeType}/{planeName}/resourceGroup/{resourcegroupID} and Azure resource scope is /subscriptions/{subscriptionID}/resourceGroup/{resourcegroupID} required: true type: string minLength: 1 x-ms-parameter-location: client x-ms-skip-url-encoding: true securityDefinitions: azure_auth: type: oauth2 description: Azure Active Directory OAuth2 Flow. flow: implicit authorizationUrl: https://login.microsoftonline.com/common/oauth2/authorize scopes: user_impersonation: impersonate your user account